release-manager

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides Python utilities for release management that perform local text and JSON processing. The implementation uses standard library modules such as re, json, and argparse, with no evidence of malicious code, network exfiltration, or unauthorized command execution.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from git commit logs and release plans, presenting a vulnerability surface for indirect prompt injection.
  • Ingestion points: Commit messages are ingested from git logs by changelog_generator.py and version_bumper.py. Release metadata is ingested from JSON files by release_planner.py.
  • Boundary markers: The skill does not implement specific delimiters or 'ignore' instructions when formatting commit messages into changelogs, which could allow embedded instructions to be presented to the agent.
  • Capability inventory: The Python scripts perform text transformation and JSON generation without using eval(), exec(), or invoking subprocesses for the ingested data.
  • Sanitization: Input is parsed via regular expressions; however, there is no filtering to prevent the agent from interpreting instructions contained within commit messages.- [EXTERNAL_DOWNLOADS]: Documentation and integration examples reference standard API interactions with well-known services, including GitHub and Datadog, for the purposes of release automation and monitoring. These references follow established security practices for DevOps tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:33 PM